Certified Information Security Manager (CISM)

Certified Information Security Manager (CISM) is an advanced certification which indicates that an individual possesses the knowledge and experience required to develop and manage an enterprise information security (infosec) program. It is offered by ISACA, a nonprofit, independent association that advocates for professionals involved in information security, assurance, risk management and governance.

The CISM certification is intended for information security managers, aspiring managers or IT consultants who support infosec program management. It is accredited by ANSI under ISO/IEC 17024:2003.

How to become a CISM

The CISM certification process includes a 200-question multiple-choice exam that is scored using 200-800 scaled scoring method. This allows performance comparisons to be made among candidates. 450 is a passing score, indicating that the individual meets a minimum consistent standard of knowledge set by the ISACA Certification Committee.

The exam covers four content areas:

  • Information security management
  • Information risk management and compliance
  • Information security program development and management
  • Information security incident management 

To qualify for the exam, applicants must have five years of verified experience in the infosec field, with a minimum of three years of infosec management experience in three or more of the CISM content areas. Experience must be gained within a 10-year period preceding the application date or within five years from the date of passing the exam.

To maintain CISM certification, individuals must sustain an adequate level of knowledge and proficiency in the field of information systems security management, complete 20 continuing professional education (CPE) hours annually and follow ISACA's Code of Professional Ethics.


This was last updated in April 2020

Continue Reading About Certified Information Security Manager (CISM)

Dig Deeper on Security industry certifications